ZeroHour
Security Affairspublished ()ingested @securityaffairs

Microsoft Patch Tuesday for May 2021 fix 4 critical flaws

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-24587
The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that all fragments of a frame

The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that all fragments of a frame are encrypted under the same key. An adversary can abuse this to decrypt selected fragments when another device sends fragmented frames and the WEP, CCMP, or GCMP encryption key is periodically renewed.

NVD description · AI analysis pending
2.63% PoC
  • ieee ieee 802.11
  • ieee mac80211
  • ieee debian linux
  • +1 more
CVE-2021-27068
Visual Studio Remote Code Execution Vulnerability

Visual Studio Remote Code Execution Vulnerability

NVD description · AI analysis pending
8.854%
  • microsoft visual studio 2019
CVE-2021-28476
Windows Hyper-V Remote Code Execution Vulnerability

Windows Hyper-V Remote Code Execution Vulnerability

NVD description · AI analysis pending
9.939%
  • microsoft windows 10
  • microsoft windows 7
  • microsoft windows 8.1
  • +1 more
CVE-2021-31166
Use-After-Free RCE in Microsoft Windows HTTP Protocol Stack (http.sys)

CVE-2021-31166 is a use-after-free vulnerability (CWE-416) in the Microsoft HTTP Protocol Stack, the kernel-mode HTTP service (http.sys) used by Windows components including IIS and WinRM. A remote, unauthenticated attacker can trigger the flaw by sending specially crafted network packets to a service that listens through http.sys, and reporting indicates WinRM servers are also impacted. Successful exploitation yields remote code execution in the kernel context, with full compromise potential (high confidentiality, integrity and availability impact), consistent with the wormable classification in vendor-adjacent reporting. Affected platforms are Windows 10 versions 2004 and 20H2 and Windows Server versions 2004 and 20H2, which were the current shipping Windows versions at the May 2021 Patch Tuesday release where the fix appeared. The issue is tracked in CISA's Known Exploited Vulnerabilities catalog (added 2022-04-06) and carries a near-certain EPSS exploitation probability (~99.8%), indicating active exploitation in the wild.

Do: Apply the May 2021 Patch Tuesday security updates for Windows 10 and Windows Server versions 2004 and 20H2, prioritizing internet-facing systems running IIS, WinRM, or other http.sys-based listeners. As an interim mitigation, restrict inbound access to HTTP and WinRM endpoints at the firewall. Confirm remediation by verifying the OS build includes the May 2021 cumulative update, and check the CISA KEV catalog action (apply updates per vendor instructions).

9.8100% KEV
  • Microsoft Windows 10 version 2004
  • Microsoft Windows 10 version 20H2
  • Microsoft Windows Server version 2004
  • +2 more
masswell over 1,000,000 vulnerable systems (tens of millions of Windows 10 2004/20H2 installs, with likely hundreds of thousands of internet-exposed servers via…
Full article245 words · extracted from securityaffairs.com · click to collapse

Microsoft Patch Tuesday for May 2021 security updates addressed 55 vulnerabilities, four are rated as Critical.

Microsoft Patch Tuesday for May 2021 security updates address 55 vulnerabilities in Microsoft Windows, .NET Core and Visual Studio, Internet Explorer (IE), Microsoft Office, SharePoint Server, Open-Source Software, Hyper-V, Skype for Business and Microsoft Lync, and Exchange Server.

Four vulnerabilities are rated as Critical, 50 as Important and the remaining one as Moderate severity.

Three of these bugs are publicly known but none are actively exploited in the wild at the time of release, 13 of these bugs were reported through the ZDI program.

The critical issues addressed by Microsoft are:

CVE-2021-31166 – HTTP Protocol Stack Remote Code Execution Vulnerability
The flaw could be exploited by an unauthenticated attacker by sending a specially crafted packet to a targeted server utilizing the HTTP Protocol Stack (http.sys) to process packets

CVE-2021-28476 – Hyper-V Remote Code Execution Vulnerability
The flaw could allow a guest VM to force the Hyper-V host’s kernel to read from an arbitrary, potentially invalid address.

CVE-2021-27068 – Visual Studio Remote Code Execution Vulnerability
CVE-2020-24587 – Windows Wireless Networking Information Disclosure Vulnerability
An attacker can trigger this issue to disclose the contents of encrypted wireless packets on an affected system.

The full list of CVEs released by Microsoft for May 2021 is available here.

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, Microsoft Patch Tuesday)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/117830/security/microsoft-patch-tuesday-may-2021.html